2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-34141HIGH8A command injection vulnerability in the access point (AP) management feature of the Zyxel ATP series firmware versions ...
CVE-2023-34140MEDIUM6.5A buffer overflow vulnerability in the Zyxel ATP series firmware versions 4.32 through 5.36 Patch 2, USG FLEX series fir...
CVE-2023-34139HIGH8.8A command injection vulnerability in the Free Time WiFi hotspot feature of the Zyxel USG FLEX series firmware versions 4...
CVE-2023-34138HIGH8A command injection vulnerability in the hotspot management feature of the Zyxel ATP series firmware versions 4.60 throu...
CVE-2023-33012HIGH8.8A command injection vulnerability in the configuration parser of the Zyxel ATP series firmware versions 5.10 through 5.3...
CVE-2023-33011HIGH8.8A format string vulnerability in the Zyxel ATP series firmware versions 5.10 through 5.36 Patch 2, USG FLEX series firmw...
CVE-2023-37475HIGH7.5Hamba avro is a go lang encoder/decoder implementation of the avro codec specification. In affected versions a well-craf...
CVE-2023-34669HIGH7.5TOTOLINK CP300+ V5.2cu.7594 contains a Denial of Service vulnerability in function RebootSystem of the file lib/cste_mod...
CVE-2023-28767HIGH8.8The configuration parser fails to sanitize user-controlled input in the Zyxel ATP series firmware versions 5.10 through ...
CVE-2023-3615HIGH8.1Mattermost iOS app fails to properly validate the server certificate while initializing the TLS connection allowing a ne...
CVE-2023-3614LOW3.3Mattermost fails to properly validate a gif image file, allowing an attacker to consume a significant amount of server r...
CVE-2023-3613LOW3.5Mattermost WelcomeBot plugin fails to to validate the membership status when inviting or adding users to channels allowi...
CVE-2023-3593MEDIUM6.5Mattermost fails to properly validate markdown, allowing an attacker to crash the server via a specially crafted markdow...
CVE-2023-3591HIGH8.2Mattermost fails to invalidate previously generated password reset tokens when a new reset token was created.
CVE-2023-3590HIGH7.5Mattermost fails to delete card attachments in Boards, allowing an attacker to access deleted attachments.
CVE-2023-3587LOW2.7Mattermost fails to properly show information in the UI, allowing a system admin to modify a board state allowing any us...
CVE-2023-3586MEDIUM5.4Mattermost fails to disable public Boards after the "Enable Publicly-Shared Boards" configuration option is disabled, re...
CVE-2023-3585MEDIUM4.3Mattermost Boards fail to properly validate a board link, allowing an attacker to crash a channel by posting a specially...
CVE-2023-3584LOW3.1Mattermost fails to properly check the authorization of POST /api/v4/teams when passing a team override scheme ID in the...
CVE-2023-3582MEDIUM4.3Mattermost fails to verify channel membership when linking a board to a channel allowing a low-privileged authenticated ...
CVE-2023-3581HIGH8.1Mattermost fails to properly validate the origin of a websocket connection allowing a MITM attacker on Mattermost to acc...
CVE-2023-3577MEDIUM4.3Mattermost fails to properly restrict requests to localhost/intranet during the interactive dialog, which could allow an...
CVE-2023-37985HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in FiveStarPlugins Restaurant Menu and Food Ordering plugin <= 2.4.6 ver...
CVE-2023-37974HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Justin Klein WP Social AutoConnect plugin <= 4.6.1 versions.
CVE-2023-36656MEDIUM5.4Cross Site Scripting (XSS) vulnerability in Jaegertracing Jaeger UI before v.1.31.0 allows a remote attacker to execute ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now